The default lifetime is 3 hours and can be extended, but never beyond 24 hours. Receiving stops when the inbox expires.
Privacy Policy · Updated August 25, 2026
A clear explanation of how test email data flows
This policy applies to MSGTMP temporary test inboxes, persistent forwarding consoles, and support communications. We process data only as needed for each feature and limit unnecessary retention through short-term storage, access controls, and user actions.
At a glance
Four key facts to know
Forwarded email in logged-in accounts is archived for 30 days so you can view its status, content, and attachments.
Sign in with a verification code sent to your real email address—no password is required. You can enable TOTP two-step verification.
Send access, correction, or deletion requests to support@msgtmp.com. We’ll verify the requester’s identity first.
1. Scope and our role
This policy explains how MSGTMP, as a service provider, handles website access data, temporary incoming email, and account forwarding data. If a team uses the site to test its product, that team remains responsible for deciding whether test data is lawful and necessary and should avoid importing production user data.
Emails sent to our addresses from external websites may contain content chosen by the sender. We cannot control what senders include, so users must create synthetic test identities only and promptly delete manageable data when they discover a misdelivery.
2. What data we process
A temporary inbox processes its random address, access token, creation and expiry times, plus the sender, subject, body, and attachments of messages delivered to it. No account is needed to read the inbox, but anyone holding the token can access it, so treat the token as a short-term credential.
The forwarding feature processes your login email, forwarding aliases, activation status, quotas, creation time, and 30-day archives. When two-step verification is enabled, we also process TOTP setup status and verification results, but never require your authenticator account password.
3. Devices, logs, and local storage
To maintain sessions and prevent abuse, we may record IP addresses, request times, browser types, endpoint paths, response statuses, and security events. Logs support rate limiting, troubleshooting, and service protection; they are not used to build advertising profiles.
Temporary inbox tokens may be stored in your browser’s local storage so an unexpired inbox can be restored after a refresh. Forwarding login credentials are primarily kept in session storage. Clearing browser data prevents this device from restoring those states, but does not automatically retract emails already sent to the address.
4. Purposes and legal basis
We use data to create inboxes, receive and display email, forward messages, show archives, verify logins, provide two-step verification, and respond to support requests. These activities are necessary to provide features you request and to maintain a secure, reliable service.
We also assess error rates, capacity, and abuse trends in aggregate. Aggregated results support engineering improvements; we do not use email content to train public-facing profiles or sell personal information.
5. Retention and deletion
Different data is retained for the duration of the relevant task rather than indefinitely. Temporary inboxes, forwarding archives, and security logs have different limits. Deletion from backups may require a reasonable rotation period, but restored data remains subject to its original purpose restrictions.
| Data type | Typical limit | What happens after expiry or deletion |
|---|---|---|
| Temporary inboxes and email | 3 hours by default; 24 hours maximum per inbox | Receiving stops and data is removed during the system cleanup cycle |
| Forwarded email archives | 30 days | Removed from active archives and no longer available to read online |
| Forwarding aliases and accounts | While the account or alias remains active | After an alias is deleted, new messages to that address are no longer forwarded |
| Security and error logs | Limited period needed for security, rate limiting, and troubleshooting | Rotated out or de-identified when expired |
| Support communications | While resolving the request and meeting necessary recordkeeping obligations | Cleared after the request is closed according to the support-record retention period |
6. Service providers, forwarding, and required disclosures
We may use hosting, storage, network, and email infrastructure providers to operate the site and provide them only with the data needed for their assigned tasks. Providers are bound by contractual, security, and confidentiality requirements and may not use the data for their own advertising or marketing.
Persistent forwarding sends incoming messages to the login email address you specify, so that email provider also processes the forwarded content. We may disclose limited information when legally required, to protect user safety, or to investigate clear abuse, and we review the scope of each request.
7. Security measures and shared responsibility
We use measures such as encryption in transit, token isolation, access controls, API rate limiting, and security logs to reduce risk. No internet service can promise absolute security, so we continually assess anomalies and limit retention to reduce potential impact.
Keep your temporary inbox token secure, sign out of the forwarding console on shared devices, and enable two-step verification for long-term accounts. Do not use a temporary address as the recovery email for an important account or include irreversible production keys in test messages.
8. Access, correction, and deletion choices
Logged-in users can copy, pause, resume, and delete aliases in the console. You can also delete individual archived messages or disable two-step verification. Temporary inboxes do not require an account and are controlled by their token; switching to a new address does not migrate old messages to the new inbox.
You can contact support to request access to, correction of, or deletion of information associated with your account. To prevent impersonation, we’ll ask you to confirm from the account email address. Some records may be retained for a limited period for security, dispute handling, or legal obligations.
9. Cookies and automated analytics
The site mainly relies on browser session storage and local storage to maintain email and login states. The deployment environment may collect necessary site-usage statistics to understand page reliability, but we do not manually add third-party advertising trackers to pages.
Your browser can clear or restrict local state, which may prevent inbox recovery or require you to log in again. Necessary state and marketing preferences are separate; we will not block core email receiving because you reject advertising profiles.
10. Children
MSGTMP is intended for development, testing, and business teams, not children, and does not knowingly collect children’s information. If a parent or guardian believes a minor has sent personal information to the site, please contact us with verifiable details to help locate it.
After confirming the request, we will delete the relevant data where feasible and prevent continued use of the associated resource. Do not resend complete sensitive content in your request; provide the time, address prefix, and issue type instead.
11. International processing
Hosting and network providers may process data outside the user’s country or region. We use safeguards such as contracts and access restrictions where required and limit data to what is needed to deliver the service.
Data protection rules vary between jurisdictions, but the purpose limits and retention boundaries described in this policy still apply to our processing. Where local law provides additional rights, users may raise a request through support.
12. Policy updates
We will update this policy and change the date at the top when features, legal requirements, or infrastructure materially change. Significant changes will be highlighted in a reasonable manner, and historical data will not suddenly be used for new purposes incompatible with the original ones.
Review the updates before continuing to use the service. If you disagree with a change, stop creating new inboxes, delete aliases you can manage, and contact us about your account request.
13. Contact us
Privacy questions, data requests, or suspected misdeliveries can be sent to support@msgtmp.com. Tell us whether the issue involves a temporary inbox or forwarding account, when it occurred, and what action you want—but do not attach passwords or complete keys to your email.
We’ll confirm receipt and reply within a reasonable period based on the request’s complexity and applicable law. For security incidents, include “security” in the subject so we can route them with priority.